Personal Information Impact Assessment (PIIA) under POPIA

By |2026-07-28T12:09:12+02:00July 27th, 2025|Categories: POPI and Data Protection|Tags: , , , , , |

A Personal Information Impact Assessment (PIIA) under POPIA is a process that helps organisations understand and mitigate the data protection risks to data subjects associated with processing personal information. Under South Africa’s Protection of Personal Information Act, 4 of [...]

Cybersecurity compliance mapping – finding every obligation

By |2025-07-31T11:41:07+02:00July 22nd, 2025|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , , |

What is cybersecurity compliance mapping? Navigating cybersecurity compliance today is like conducting a precise archaeological dig: you must carefully uncover each layer of obligations without damaging your organisation's underlying structure. Each jurisdiction, sector, and obligation presents distinct challenges, demanding meticulous [...]

Data classification best practices

By |2025-07-29T11:35:52+02:00July 16th, 2025|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , , , |

We've all got that chaotic drawer at home — a messy collection of old chargers, mystery keys, forgotten receipts, and batteries that may or may not work. While such clutter at home might only cause mild frustration, allowing your business [...]

Cybersecurity is mission-critical

By |2025-07-10T10:47:28+02:00July 10th, 2025|Categories: Cybersecurity Law|Tags: |

Imagine your business as a body, thriving and responding to opportunities, with your digital systems acting as its nervous system. Just as any impairment to nerves can paralyse a body, a cybersecurity breach can disrupt or incapacitate your organisation. Cybersecurity [...]

Northbound Processing v SA Diamond Regulator | AI-generated case law

By |2025-07-03T10:54:38+02:00July 1st, 2025|Categories: AI Governance, Life@Law|Tags: , , |

The Northbound Processing v SA Diamond Regulator case highlights the risks of citing AI-generated case law in South African courts. It concerns the urgent release of a refining licence linked to a disputed business sale and highlights the consequences of [...]

Zimbabwe’s Cyber and Data Protection Act | Overview

By |2025-08-27T13:24:27+02:00June 30th, 2025|Categories: POPI and Data Protection|Tags: , , , , |

Zimbabwe’s Cyber and Data Protection Act clearly sets out how organisations must collect, use, and protect personal information. Alongside the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, it forms a comprehensive legal [...]

Case study: 23andMe data breach

By |2025-07-03T11:08:33+02:00June 26th, 2025|Categories: POPI and Data Protection|Tags: , , |

The 23andMe data breach exposed highly sensitive personal and genetic information. Canadian and UK regulators found that 23andMe failed to implement adequate security measures and violated their respective data protection laws. This breach highlights how poor security and slow response [...]

Inzalo v Chief Albert Luthuli Municipality | Data ownership

By |2026-02-12T14:42:52+02:00June 25th, 2025|Categories: Contracts, Information Law, Intellectual Property Protection, IT Law|Tags: , , , , |

In Inzalo v Chief Albert Luthuli Municipality, the court examined disputes over public procurement, contractual obligations, and alleged unlawful enrichment in the context of data ownership. This case offers a key lesson that you must be able to analyse and […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Lawyers must use AI professionally

By |2025-08-24T18:54:12+02:00June 23rd, 2025|Categories: AI Governance, Life@Law|Tags: , , , |

Lawyers must use AI professionally to preserve the doctrine of precedent. There are a number of globally reported incidents (like fake case-law citations in the UK) illustrating where lawyers have failed to use AI professionally with significant consequences. There is [...]

Practical data classification framework

By |2025-07-04T07:04:30+02:00June 21st, 2025|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , |

Managing data effectively in any organisation can feel like navigating an intricate roundabout without clear signage — a confusing, inefficient, and costly process prone to mistakes. Poor data quality can significantly impact your organisation's decision-making capabilities, resulting in operational inefficiencies, [...]